fix(store,doctor): doc-verifier findings on the trust surfaces
Some checks failed
Security / Security check (push) Failing after 1s

The doc-verifier pass over the new trust/exposure surfaces came back
PASS with five improvements, all applied:
- the store policy notice gains a 'Learn more' into the security doc
  (the notice named security.require_signatures but not where it
  lives)
- 'blocked' disables the trust gate's install button — an active
  button contradicted the 'install would be refused' statement right
  above it (guard test added)
- the unknown-exposure tooltip now says what the operator can do
  (check where the name resolves)
- dead l10n key verifPillUnverified removed (unverified is the
  page-level notice, never a card pill)
- stale header comment in install_verification.dart corrected

Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
This commit is contained in:
flemming-it 2026-07-21 13:23:58 +02:00
parent 2f076ccf29
commit bef2dbe988
9 changed files with 34 additions and 22 deletions

View file

@ -105,6 +105,18 @@ void main() {
);
});
testWidgets('blocked disables the install button', (tester) async {
await tester.pumpWidget(
_host(ChainInstallConfirmDialog(item: _item(verification: 'blocked'))),
);
await tester.pumpAndSettle();
// The statement says the hub would refuse the button must
// not contradict it.
expect(find.text('Installation würde abgelehnt'), findsOneWidget);
final button = tester.widget<FilledButton>(find.byType(FilledButton));
expect(button.onPressed, isNull);
});
testWidgets('trust gate keeps the generic note for old hubs', (tester) async {
await tester.pumpWidget(_host(ChainInstallConfirmDialog(item: _item())));
await tester.pumpAndSettle();